Back to skill

Security audit

Smart Photo Editor

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent photo-editing skill, but users should understand that AI features can send selected images and metadata to external services.

Install only if you are comfortable with selected photos being processed by Seedream and, when configured, your Cloudflare R2 worker. Strip EXIF/location metadata before cloud AI edits if the images are sensitive, pin Python dependencies in your own environment, and choose output paths carefully to avoid overwriting important files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:161
Finding

Unpinned Third-Party Dependencies Installed from a Mutable Package Index

Content
View full analysis
Remediation
View remediation
rembg== piexif== exif== ``` 2. Generate and verify cryptographic hashes for every package and transitive dependency. 3. Install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Maintain a lock file generated from a controlled build environment. 5. Document the expected package index and recommend disabling unexpected extra indexes to reduce dependency-confusion exposure. 6. Review dependency updates before changing pinned versions, including transitive dependencies and build-system requirements. 7. Prefer prebuilt, verified wheels where practical and install dependencies in a dedicated, least-privileged virtual environment. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/edit.py:350
Finding

External AI Uploads Preserve Potentially Sensitive EXIF Metadata

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (49)

Tainted flow: 'req' from os.environ.get (line 249, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The skill reads a destination URL from SEEDREAM_UPLOAD_WORKER_URL and uploads raw user image data plus an authorization bearer token to that remote endpoint. Because the endpoint is not pinned or allowlisted, a hostile or misconfigured environment can redirect uploads to an attacker-controlled server, causing exfiltration of sensitive images and credential exposure in a photo-editing skill where users may not expect third-party transfer.

Content

Scanner excerpt · scripts/edit.py (reported line 258)May include surrounding context.

python
req.add_header("User-Agent", "Mozilla/5.0")

        try:
            with urllib.request.urlopen(req, timeout=120) as resp:
                body = resp.read().decode()
                result = _json.loads(body)
                url = result.get("url", "")

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest description materially understates behavior by omitting scene replacement, document rectification, smart compression, HDR processing, and especially external image upload to Cloudflare R2. Security reviewers and users may approve the skill for simple editing while missing that it can transmit user images to third-party infrastructure and perform broader operations than declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The manifest description materially understates behavior by omitting scene replacement, document rectification, smart compression, HDR processing, and especially external image upload to Cloudflare R2. Security reviewers and users may approve the skill for simple editing while missing that it can transmit user images to third-party infrastructure and perform broader operations than declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The manifest description materially understates behavior by omitting scene replacement, document rectification, smart compression, HDR processing, and especially external image upload to Cloudflare R2. Security reviewers and users may approve the skill for simple editing while missing that it can transmit user images to third-party infrastructure and perform broader operations than declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The manifest description materially understates behavior by omitting scene replacement, document rectification, smart compression, HDR processing, and especially external image upload to Cloudflare R2. Security reviewers and users may approve the skill for simple editing while missing that it can transmit user images to third-party infrastructure and perform broader operations than declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest description materially understates behavior by omitting scene replacement, document rectification, smart compression, HDR processing, and especially external image upload to Cloudflare R2. Security reviewers and users may approve the skill for simple editing while missing that it can transmit user images to third-party infrastructure and perform broader operations than declared.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

| SEEDREAM_UPLOAD_WORKER_URL | ✅ Yes | Your worker URL, e.g. https://your-worker.your-subdomain.workers.dev. |

bash
# Add to your shell profile or ~/.openclaw/.env
export SEEDREAM_UPLOAD_TOKEN="your-token-here"
export SEEDREAM_UPLOAD_WORKER_URL="https://your-worker.your-subdomain.workers.dev"

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code uploads user-provided images to an external Cloudflare Worker/R2 service, which is a material data exfiltration behavior inside a local photo-editing skill. Since the transfer is built into the processing path for larger images and is not clearly disclosed at the action point, sensitive personal photos may leave the local environment unexpectedly.

Content

No source excerpt is available for this finding.

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

The operation writes to a user-supplied output path without enforcing a confined workspace, and the generic path validation only blocks a handful of system directories. An attacker who can influence arguments or batch JSON can overwrite arbitrary user-accessible files, including dotfiles, SSH config, or application data, which is dangerous even if root-owned system paths are partially blocked.

Content

Scanner excerpt · scripts/edit.py (reported line 857)May include surrounding context.

python
if rembg_cmd and tool in ("auto", "rembg"):
            try:
                self._log("Using rembg for background removal...")
                result = subprocess.run(
                    [rembg_cmd, "i", image, output],
                    capture_output=True, text=True, timeout=60
                )

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

Background removal also writes to an attacker-influenced output path with insufficient confinement, creating the same arbitrary file overwrite risk. Because this function is likely exposed as a normal editing action, it gives a simple path for misuse without requiring advanced conditions.

Content

Scanner excerpt · scripts/edit.py (reported line 901)May include surrounding context.

python
bg_hex = '#%02x%02x%02x' % bg_color

                    # Make detected background color transparent
                    result = subprocess.run(
                        [im_cmd, image, "-fuzz", "20%", "-transparent", bg_hex, output],
                        capture_output=True, text=True, timeout=30
                    )

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

The crop operation passes a user-controlled output filename directly to ImageMagick after only weak validation, allowing arbitrary overwrite of files the current user can write. In an agent setting where task JSON may be influenced externally, this can be abused to clobber important local files or stage follow-on compromise via modified user configuration.

Content

Scanner excerpt · scripts/edit.py (reported line 1037)May include surrounding context.

python
if im_cmd:
            try:
                result = subprocess.run(
                    [im_cmd, image, "-crop", f"{width}x{height}+{x}+{y}",
                     "+repage", output],
                    capture_output=True, text=True, timeout=30

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/exif_utils.py (reported line 340)May include surrounding context.

python
import subprocess
    for cmd in ["magick", "convert"]:
        try:
            subprocess.run([cmd, "-strip", output, output],
                         capture_output=True, timeout=10)
            print(f"✓ EXIF stripped with {cmd}: {output}")
            return

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes Seedream AI for object removal and restoration but does not clearly warn users that images and prompts may be sent to an external service. This can expose sensitive photos, embedded metadata, or confidential visual content without informed consent, especially in a photo-editing skill where users may process personal images.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation provides direct instructions for removing watermark or logo regions, which can facilitate copyright circumvention and misuse of protected media. In the context of a photo-editing skill, this capability is especially risky because it is presented as a normal workflow without limitation, warning, or legitimate-use framing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises substantial capabilities involving shell execution, filesystem access, environment-variable use, and network access, but does not declare any tool scope or permissions boundary. That omission weakens reviewability and least-privilege enforcement, making it easier for the skill to access sensitive files, credentials, or external services without explicit user/operator awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level description does not clearly warn that AI features may send user images to external cloud services, including VolcEngine Ark and optionally Cloudflare Worker/R2. This lack of prominent disclosure can lead to unintentional exfiltration of sensitive images, metadata, or personal content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Very broad trigger phrases increase the chance of unintended activation, causing the skill to process images, invoke shell tools, or send content to external AI services when the user did not explicitly intend to use this skill. In a skill with networked image handling and file operations, overbroad activation meaningfully increases privacy and safety risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents optional upload of user-supplied images to a self-deployed Cloudflare Worker/R2 endpoint, which is a significant data egress behavior not clearly surfaced in the top-level description or permission model. User images may contain sensitive personal, biometric, or embedded-location information, so silent or weakly disclosed off-device transfer materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Scene replacement via multi-reference image fusion is a materially different and more powerful capability than basic photo editing, and it relies on external AI processing of user images/prompts. Under-disclosing this increases the chance of accidental approval of a skill that performs cloud-based compositing and submits multiple reference images to an external model provider.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/edit.py (reported line 277)May include surrounding context.

python
def _seedream_available(self) -> bool:
        """Check if Seedream skill is available."""
        seedream_skill = os.path.expanduser("~/.openclaw/skills/byted-ark-seedream-skill/SKILL.md")
        return os.path.exists(seedream_skill)

    def _call_seedream(self, image_path: str = None, prompt: str = "",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Large reference images are automatically uploaded remotely when they exceed the threshold, but the user is only warned on failure and not informed beforehand that their image may be sent off-host. In a photo editor, silent network transmission of personal images is especially sensitive because users often assume purely local processing.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/edit.py (reported line 392)May include surrounding context.

python
]

        try:
            result = subprocess.run(
                cmd,
                capture_output=True,
                text=True,

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes object removal, background removal, old photo restoration, and basic edits. This file additionally implements a distinct replace-scene capability that composites a subject into a new generated scene using multi-reference AI fusion, which is not mentioned in the manifest description and materially expands the skill’s behavior.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/edit.py (reported line 847)May include surrounding context.

python
venv_rembg = self.venv_python.replace("/bin/python", "/bin/rembg")
        for cmd_candidate in ["rembg", venv_rembg]:
            try:
                subprocess.run([cmd_candidate, "--help"],
                             capture_output=True, timeout=5)
                rembg_cmd = cmd_candidate
                break

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/edit.py (reported line 857)May include surrounding context.

python
if rembg_cmd and tool in ("auto", "rembg"):
            try:
                self._log("Using rembg for background removal...")
                result = subprocess.run(
                    [rembg_cmd, "i", image, output],
                    capture_output=True, text=True, timeout=60
                )

Static analysis

No suspicious patterns detected.